What I Can Help With
I work where software, architecture, and security meet: assessing how systems fail,
building practical mitigations, and creating tools when off-the-shelf answers are not enough.
01Security Research & Assessment
Attacker-led assessment of applications, platforms, protocols, infrastructure, and product
architectures. Useful when you need a deeper view than a checklist penetration test.
- Vulnerability research and exploitability analysis
- Reverse engineering of native code, protocols, and embedded systems
- Windows, Linux, cloud, network, and distributed-system attack surfaces
02Threat Modelling
Structured threat modelling for products, deployments, and delivery pipelines, with clear
engineering actions rather than abstract risk documents.
- Architecture review and trust-boundary analysis
- CI/CD, signing, artefact integrity, and supply-chain attack paths
- Model creation, workshop facilitation, and process design
03Secure Development Lifecycle
Practical SDL consulting for teams that need security built into delivery without slowing
engineering to a crawl.
- Security requirements, design review, and secure coding guidance
- SAST, SCA, vulnerability triage, and remediation workflows
- Disclosure, bug bounty, and vulnerability management processes
04Bespoke Security Tooling
Custom software for analysis, automation, integration, and specialist workflows where
standard tools do not quite fit.
- Python, C, C++, C#, Java, Kotlin, JavaScript, Win32, and Linux tooling
- Fuzzing harnesses, protocol tooling, parsers, and workflow automation
- Internal platforms for repeatable security assessment and reporting
Areas Of Depth
Experience across fintech, telecoms, government intelligence, distributed ledger systems,
endpoint platforms, and sensitive engineering environments.
How Engagements Usually Work
- Scope the problem.
Clarify the asset, threat, constraints, and the decision you need to make.
- Investigate deeply.
Review architecture and code, test assumptions, build tooling, and validate attack paths.
- Leave useful output.
Document findings, prioritise fixes, and help teams turn risk into engineering work.
Need specialist security input?
I can help with focused assessments, architecture reviews, threat models, secure engineering
strategy, or bespoke tooling for hard technical problems.